Latest stories — Page 89

The Data You Don't Know You Have Is the Data That Will Burn You
DSPM tools are selling fast and consolidating faster — here's why security teams are scrambling to find the data they forgot existed.

Cisco Uncovers Major Weaknesses in Leading AI Models
Relying solely on single-turn benchmarks could mislead your AI security assessments.

AI's Role in the Battle of Stolen Credentials
Security teams grapple with AI-driven credential abuse, leaving many playing catch-up.

SymJack: How a Rogue Symlink Turns Your AI Coding Agent Into a Supply Chain Weapon
A newly documented attack technique exploits AI coding agents through malicious repositories and disguised symlinks, silently planting attacker-controlled MCP servers deep inside developer environments.

AI Risk Summit Returns August 11–12 at Half Moon Bay for Its Third Year
CISOs, policymakers, and AI researchers converge on the Ritz-Carlton for two days of hard conversation about what enterprise AI risk actually looks like in practice.

Account Takeover Flaw in Pretalx CFP Tool Let Attackers Accept Any Conference Talk
An account takeover vulnerability in the open-source call-for-papers platform Pretalx could allow an unauthenticated attacker to manipulate submission outcomes, researchers at Novee have found.

Microsoft Catches Chatbots Pointing Users at Cryptojacking Sites
A campaign tracked by Microsoft Defender Experts is poisoning AI assistant answers so that download recommendations lead to miner-laden installers.

Britain's Cyber Spymaster Calls AI an Unstoppable Force and Points the Finger at Moscow
The head of GCHQ's signals intelligence arm delivered a rare public speech warning that Russia is waging sustained gray-zone aggression — and that artificial intelligence will define who wins the next phase of that conflict.

The SOC's Real Job Isn't Triage. It's Killing Incidents Before They Get Named.
Three workflow shifts that compress detection-to-containment from hours into the window before an alert becomes a ticket.

Gitea Patches Unauthenticated Container Image Disclosure Flaw in 1.26.2
CVE-2026-27771 allowed anonymous pulls of private container images from all Gitea deployments prior to version 1.26.2, according to maintainers.

Shadow AI Is Now a Compliance Problem, Not Just an IT One
Employees are running unsanctioned AI assistants by the handful. Regulators are starting to ask who approved them, and under which control framework.

CrowdStrike, Google and Shadowserver Pull the Plug on GlassWorm's C2
A coordinated takedown severed every known command channel of the developer-targeting worm — for now.

Grandoreiro Hits Spain Again, BTMOB Spreads on Android in Brazil
Two parallel banking trojan campaigns are pulling in victims across Iberia, Mexico, and Brazilian Android users. The lures are mundane. The payloads are not.

The npm Package That Reached Into Claude's Sandbox
A bait package called mouse5212-super-formatter quietly siphoned files from the directory Anthropic's Claude uses to handle user uploads, exfiltrating them to a GitHub repo controlled by the author.

Glassworm's blockchain command channel went down. Nobody will say who pulled the plug.
Researchers say the developer-targeting botnet is offline after its Solana and BitTorrent DHT C2 was disrupted. The mechanics of the takedown, and who authorised it, remain unexplained.

CISA Gives Federal Agencies Four Days to Kill a cPanel Plugin Bug Already Being Exploited
The LiteSpeed plugin sits on millions of shared hosting accounts. CISA's compressed timeline says the quiet part loud: someone's already inside.

MuddyWater Targets Global Organizations with DLL Side-Loading
Iranian group MuddyWater exploits DLL side-loading in espionage affecting nine nations.

AppOmni Unveils Marlin AI for SaaS Security Analysis
Marlin AI steps in with autonomous SaaS threat investigations.

Megalodon Campaign Pushed 5,718 Malicious Commits Into GitHub Repos in Six Hours
An automated backdooring operation abused compromised GitHub credentials to silently inject base64-encoded bash payloads into CI/CD workflows across more than 5,500 public repositories on May 18.

CERT-In Tightens the Clock: Patch Internet-Facing Bugs in 12 Hours
India's national CERT cites AI-assisted exploit development as the reason small teams now have less than a working day to close exposed holes.

The Bot That Learned to Lie: Inside the New Generation of AI-Driven DDoS
Defenders describe attack waves that pause, study traffic patterns, and resume from fresh infrastructure — behavior that looks less like a script and more like a sparring partner.